Privacy Policy for the Use of mirARcle Services
Last Updated: April 02, 2025
Owner
mirARcle AG
CompanyStreet 2
6300 Zug
Switzerland
Contact: contact@mirarcle.com
Chief Data Officer
Our Chief Data Officer (CDO) oversees data protection practices and ensures compliance with all applicable legal requirements. Although the appointment of a CDO is not mandatory under the Swiss Federal Act on Data Protection (nFADP), we have voluntarily established this role to enhance our data oversight, particularly regarding sensitive information. For any data protection inquiries, please contact:
Email: cdo@mirarcle.com
Introduction
We, mirARcle AG ("mirARcle", "we", or "us"), are committed to safeguarding your personal data and ensuring transparency in our information-handling practices. This Privacy Policy outlines our methods for data collection, use, processing, and protection across our website, app, plugins, and other services. Our data processing activities comply with the General Data Protection Regulation (GDPR), the Swiss Federal Act on Data Protection (nFADP), and applicable United States privacy regulations, ensuring that your privacy rights are fully respected and protected.
We adopt stringent technical and organizational measures to secure personal data. Whether we act independently or in collaboration with third parties, we are committed to informing you transparently about the type, scope, purpose, duration, and legal basis for the processing of your personal data, as required under Articles 13 and 14 of the GDPR.
Definitions
In accordance with Art. 4 GDPR, this Privacy Policy is based on the following definitions:
- "Personal Data" (Art. 4 No. 1 GDPR) refers to any information relating to an identified or identifiable natural person ("Data Subject"), including names, identification numbers, location data, and online identifiers. Data that can be linked with other information to identify an individual is also considered personal data.
- "Processing" (Art. 4 No. 2 GDPR) includes any operation performed on personal data, such as collection, storage, use, disclosure, alteration, or destruction. Processing may be performed manually or electronically.
- "Controller" (Art. 4 No. 7 GDPR) is the entity that determines the purposes and means of processing personal data. As the controller, mirARcle is responsible for ensuring that all processing complies with applicable data protection regulations.
- "Processor" (Art. 4 No. 8 GDPR) is any entity that processes personal data on behalf of the controller, subject to contractual obligations that ensure compliance with our instructions and legal requirements.
- "Consent" (Art. 4 No. 11 GDPR) is a freely given, specific, informed, and unambiguous indication of the data subject's wishes regarding the processing of their personal data. Consent may be withdrawn at any time without affecting the lawfulness of prior processing.
Amendment of this Privacy Policy
We review and update this Privacy Policy regularly to reflect changes in legal requirements, technological advancements, and our internal practices. Updates will be communicated without undue delay. This Privacy Policy is effective as of April 02, 2025. We encourage you to review it periodically to remain informed about our data protection practices.
Data Collection and Processing
Collection of Personal Data
- When you use mirARcle services, we collect only the personal data necessary for the delivery and improvement of our services. This data may include your name, location data, IP address, and email address. The collection is strictly limited to what is essential for service functionality and personalized user experience.
- We process personal data in the European Union, Switzerland, and other jurisdictions as required, ensuring strict adherence to all applicable data protection laws. Our practices are designed to minimize data collection while maintaining service efficiency.
Legal Basis for Processing
Our processing of personal data is based on one or more of the following legal grounds:
- Consent (Art. 6 para. 1 lit. a GDPR)
- Contract performance (Art. 6 para. 1 lit. b GDPR)
- Compliance with legal obligations (Art. 6 para. 1 lit. c GDPR)
- Protection of vital interests (Art. 6 para. 1 lit. d GDPR)
- Public interest (Art. 6 para. 1 lit. e GDPR)
- Legitimate interests (Art. 6 para. 1 lit. f GDPR)
You have the right to withdraw your consent at any time. Withdrawal will not affect the lawfulness of processing conducted prior to the withdrawal.
Data Processing during Download and Use
- When you download our app, certain personal data—such as your email address, username, and device information—may be collected by the app store. Such collection is governed by the app store's own privacy policies, over which we have no control.
- For app functionality and ongoing service delivery, we collect and process the necessary personal data based on contractual performance and our legitimate interests, thereby ensuring a secure and efficient user experience.
Cookies and Similar Technologies
We employ cookies and similar technologies to enhance your experience on our services. The following types of cookies may be used:
- Strictly Necessary Cookies: These are essential for the basic operation of our services.
- Functional Cookies: These enable us to remember your preferences and improve service usability.
- Analytical/Performance Cookies: These allow us to monitor service usage and improve our offerings.
- Advertising Cookies: These help deliver personalized advertisements based on your browsing behavior.
You may manage or disable cookies through your browser settings; however, please note that this may affect the functionality of our services. To learn more about cookies, please visit allaboutcookies.org.
To opt out of interest-based advertising, you can use the following links:
Do Not Track
Some browsers send “Do Not Track” signals; however, we currently do not modify our practices in response to these signals. More information about Do Not Track can be found at allaboutdnt.com.
US Data Protection and CCPA Compliance
For users in the United States, and particularly California residents, additional data protection rights may apply under the California Consumer Privacy Act (CCPA) and other state-specific laws. While our primary data processing is governed by the GDPR and the Swiss Federal Act on Data Protection, we also adhere to relevant US privacy standards. California residents have the right to:
- Request access to the personal data we hold about them.
- Request deletion of their personal data.
- Opt out of the sale of their personal data, where applicable.
If you are a resident of California or any other US state with specific privacy laws, please contact our Chief Data Officer at cdo@mirarcle.com for further information or to exercise your rights.
Storage of Personal Data
- We retain personal data only for the duration necessary to fulfill the purposes for which it was collected or as required by legal obligations.
- Personal data is securely stored on servers located in Switzerland and the EU, protected by state-of-the-art security measures. In cases of legal proceedings or disputes, data may be retained until resolution.
Security of Personal Data
- We implement robust technical and organizational measures, including encryption and access controls, to safeguard your personal data against unauthorized access, loss, or destruction.
- Our Chief Data Officer continually monitors and enhances these security measures to ensure ongoing protection.
Data Processing by Third Parties
- We may engage trusted third-party processors to support our service delivery. These processors are contractually required to comply with our data protection standards and all relevant legal requirements.
- We disclose personal data to government authorities only when legally mandated.
Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, personal data may be transferred as part of the transaction. We will take reasonable steps to ensure that any recipient of your personal data agrees to comply with this Privacy Policy or provides equivalent data protection safeguards.
Your Rights
As a data subject, you are entitled to:
- Right to Information: Request details about your personal data and its processing.
- Right to Rectification: Request corrections for inaccurate or incomplete data.
- Right to Objection: Object to processing based on legitimate interests.
- Right to Erasure: Request deletion of your data when it is no longer necessary or if consent is withdrawn.
- Right to Restriction: Request limitation of processing under certain circumstances.
- Right to Data Portability: Request a structured, machine-readable copy of your personal data.
For additional rights under the CCPA (if you are a California resident), such as the right to opt out of data sales, please contact us at cdo@mirarcle.com.
To exercise any of these rights, please contact our Chief Data Officer at cdo@mirarcle.com. We may require additional verification to process your request. Note that certain rights may be subject to limitations, and we may retain data as required for backup, archiving, or legal compliance.
International Visitors
Our Services are hosted primarily in Switzerland and the European Economic Area (EEA). If you access our Services from other regions, please be aware that your personal data may be transferred, stored, and processed in Switzerland or the EU in accordance with applicable data protection laws. By using our Services, you consent to these transfers and processing.
Other Sites, Mobile Applications, and Services
Our Services may include links to third-party websites, mobile applications, or other online services that are not operated by us. We are not responsible for the privacy practices or content of these third parties. We encourage you to review the privacy policies of any other sites you visit.
Children's Privacy
Our services are not intended for children under the age of 13 (or under 16 in the EU). We do not knowingly collect personal data from children. If we inadvertently collect data from a child, we will promptly delete it. If you become aware of any such data collection, please contact us immediately.
Governing Law and Jurisdiction
This Privacy Policy and any disputes arising from it are governed by the laws of Switzerland, without regard to conflict of law principles. Any legal proceedings shall be brought exclusively in the competent courts of Zug, Switzerland.
Changes to Our Privacy Policy
We may update this Privacy Policy as needed to reflect changes in legal requirements or our practices. Continued use of our Services after such changes constitutes acceptance of the updated policy. We encourage you to review this document periodically.
Contact Information
For questions regarding this Privacy Policy, to exercise your rights, or for further inquiries about our data protection practices, please contact our Chief Data Officer at:
mirARcle AG
CompanyStreet 2
6300 Zug
Switzerland
Email: cdo@mirarcle.com
We are committed to protecting your privacy and appreciate your trust in us.